CVE-2022-47208: Command Injection
The “puhttpsniff” service, which runs by default, is susceptible to command injection due to improperly sanitized user input. An unauthenticated attacker on the same network segment as the router can execute arbitrary commands on the device without authentication.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-47208?
CVE-2022-47208 is considered a high severity vulnerability that allows unauthenticated attackers to execute arbitrary commands on the vulnerable device.
How do I fix CVE-2022-47208?
To fix CVE-2022-47208, update the firmware of your Netgear Nighthawk device to a version higher than 1.0.9.90.
Which devices are affected by CVE-2022-47208?
CVE-2022-47208 affects the Netgear Nighthawk models with firmware versions up to 1.0.9.90, including AX1800, AX2400, AX3000, AX5400, AX6000, and AX11000.
Can CVE-2022-47208 be exploited remotely?
CVE-2022-47208 requires the attacker to be on the same network segment as the router, making remote exploitation unlikely.
Is exploit code available for CVE-2022-47208?
Currently, there is no public exploit code available for CVE-2022-47208, but the vulnerability is serious enough to warrant immediate attention.